
We found results for “”
WS-2013-0004
Good to know:


Date: June 27, 2013
The "methodOverride" let the http post to override the method of the request with the value of the post key or with the header, which allows XSS attack.
Language: Java
Severity Score
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix

Upgrade Version
Upgrade to version facuramirez/mercado-libre-php-sdk - no_fix;marcelojeff/php-sdk - no_fix;squareproton/bond - no_fix;connect - 2.8.1;seyon/nodejs-chat-bundle - no_fix;crisnao2/meli - no_fix;agapito78/php-sdk - no_fix;badsyntax/jquery-spellchecker - 0.2.4;mpcmf/mpcmf-web-app - 1.0.0.x-dev;mpcmf/mpcmf-web-app - no_fix;yuan1994/wechat_web_devtools - 0.10.102800;ng-grid - 2.0.4;ephp/node - no_fix;jonatasavila-mercadolibre/php-sdk - 1.0.0;micheldamasceno/mercadolibre - no_fix;alejoasotelo/mercadolibre-php-sdk - no_fix;org.webjars.bower:messageformat:0.3.0-1;org.webjars.npm:connect:2.12.0;org.webjars:browser-sync:no_fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | CHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | NONE |